GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques
During an incident response engagement, you review Windows Security event logs and observe a series of 4624 logons with Logon Type 3 originating from a single workstation. The account name is the computer account of a server, and the source workstation is a user's desktop that normally never authenticates to the target server. Which post-exploitation technique is most consistent with this pattern?
⚠ Common exam trap
The trap here is assuming any 4624 Type 3 event is benign file-share access rather than recognizing the mismatch between the claimed machine account and the actual source workstation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pass-the-Hash using the machine account hash to authenticate laterally
Pass-the-Hash allows an adversary to authenticate using a captured NTLM hash, and machine account hashes are equally usable. A Type 3 network logon claiming to be a server's machine account but originating from an unrelated workstation is a classic lateral movement signature. Kerberoasting, Golden Ticket, and DCSync leave different artifacts such as 4769, 4768, or 4662 events, not this logon pattern.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Kerberoasting of the server's service account
Why it's wrong here
Kerberoasting requests service tickets for accounts with SPNs and cracks them offline, producing event 4769 rather than 4624 Type 3 logons. It does not immediately generate network logons from arbitrary workstations. The pattern here is an authentication event, not a ticket request, so Kerberoasting does not fit.
- ✓
Pass-the-Hash using the machine account hash to authenticate laterally
Why this is correct
Pass-the-Hash reuses an NTLM hash to authenticate without knowing the plaintext password. Machine accounts can be abused the same way. A Logon Type 3 (network) from an unexpected workstation using a server's machine account strongly indicates credential reuse of a captured machine hash for lateral movement. This aligns with the observed anomaly.
- ✗
Golden Ticket creation using the KRBTGT hash
Why it's wrong here
A Golden Ticket forges a TGT and typically results in 4768 or 4769 events, often with anomalous encryption types or lifetimes. It does not produce a 4624 Type 3 logon tied to a machine account from a random workstation. The visible artifact here is a network logon, so Golden Ticket is not the best match.
- ✗
DCSync replication of directory credentials
Why it's wrong here
DCSync impersonates a domain controller to pull password hashes via DRSUAPI, generating 4662 events referencing replication GUIDs. It does not create 4624 Type 3 logons from a user workstation. Since the observed event is a network logon, DCSync is not the technique in play.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.